Kaspersky Uncovers 'Red October' Cyber Attack On Eastern Europe

By Khurram Aziz email: k.aziz@mobilenapps.com | Jan 15, 2013 11:44 AM EST

Share This Story

  • Print
  • Email

Russian antivirus firm Kaspersky Labs claims to have found a cyber attack that may have been stealing confidential government documents since 2007 from mostly Eastern Europe and Central Asia, but also in Western Europe and North America.

Follow us

The malware, which the company is calling "Red October" after the 1990 Tom Clancy espionage thriller, targeted government institutions such as embassies, nuclear research centers and oil and gas institutes.

Kaspersky is publishing the entire research that led to the discovery of the cyber attack on its Web site.

"During the past five years, a high-level cyber-espionage campaign has successfully infiltrated computer networks at diplomatic, governmental and scientific research organizations, gathering data and intelligence from mobile devices, computer systems and network equipment," it reads

"The campaign, identified as "Rocra", short for "Red October", is currently still active with data being sent to multiple command-and-control servers, through a configuration which rivals in complexity the infrastructure of the Flame malware. Registration data used for the purchase of C&C domain names and PE timestamps from collected executables suggest that these attacks date as far back as May 2007."

Kaspersky said it found several Russian words embedded in the malware's code, suggesting the attackers are of Russian-speaking origin. Words such as  "Zakladka" appear in the malware, which, in Russian and Polish, can mean "bookmark" or "undeclared functionality" in slang.

Howeverr, Vitaly Kamluk, chief malware analyst at Kasperksy Lab, told TechWeekEurope there was no "strict evidence" a nation state was behind the attack. It was, nevertheless, one of the most targeted campaigns seen to date

"In Red October, the attackers seem to be hunting for specific organisations. They are interested in high-quality, high-profile information," Kamluk told TechWeekEurope. "That explains why the number of infected machines is so low - just over 300 machines... but every target was specifically selected. What makes this attack different from Flame and others is that every attack was planned very carefully.

"They shaped every attack attempt very carefully, and even created specific modules for targets. Not all the targets received the same binaries.

"Inside the malware, you can find a user ID, which actually shows it is a specific piece of malware compiled for a specific [target]."

Kaspersky said that it named the virus Red October because it was first brought to its attention in October 2012 after a tipoff from an anonymous source. The antivirus firm intends to publish the full report into the spy campaign later this week on its Web site.

Get the Most Popular Mobile&Apps Stories in a Weekly Newsletter

© 2013 Mobile & Apps All rights reserved. Do not reproduce without permission.

Join Our Conversation

Smartphones
Galaxy S4 Google EditionSamsung Galaxy S4 'Google Edition' Will Be Available In U.S. Only?
Sony Xperia UL Reaches Japan With New Camera Features
Samsung Galaxy S4 'Rugged' Version Appears In Leaked Photos
Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Tablet / Laptop / PC
Samsung Galaxy Tab 3 8.0 Leaked ImageSamsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Nexus 7 Refresh Teased In Google+ Hangouts Video, Sports Glowing Notification Light
Gadgets
Ouya Android-Powered $99 Game ConsoleOuya Will Be At E3 2013, But Not Where You Think
Next Microsoft Xbox To Sport Dashboard UI Update And Tile Changes
Google Media Streamer Hits FCC To Replace Nexus Q
Google Glass Raises Lawmakers' Concerns: Congress Demands Answers About Privacy
OS / Software
Galaxy S4 Google EditionSamsung Galaxy S4 'Google Edition' Will Be Available In U.S. Only?
Android 5.0 Key Lime Pie Mentioned In Google I/O 2013: Is Google Working On The Firmware Update?
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
Samsung Galaxy S4 Mega Confirmed By Samsung In WatchOn Change Log?
Internet / Social Media
FaceTimeAT&T Promises Cellular Video Calls, Mobile Video Chat For All Customers
Flickr Boasts 'Spectacular' Redesign, Offers A Whopping 1TB Of FREE Storage
Download 40 GB In A Second: Researchers Set Up World's Fastest Wi-Fi Network In Germany
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
What's App
Galaxy S4 White FrostSamsung Galaxy S4 App Contest Boasts $800,000 Total Prizes For Talented Devs
Intellicam App Brings First Hands-Free Camera Feature To Windows Phone 8
Seven New Apps Coming To Google Glass: Facebook, Twitter, And Evernote Included
Itsdagram Available Now For Windows Phone: Best Instagram Client Around

DON'T MISS

A photo allegedly taken with the Samsung Galaxy Note 3
Photo Taken With Samsung Galaxy Note 3 'Leaked' Online
The photo is posted by SamMobile and the screenshot of the EXIF data of the image shows that the
Nokia Lumia 928
Verizon Exclusive Nokia Lumia 928 Now $49.99 At Online Retailers
Want a Lumia 928 on Verizon Wireless? Pick it up from RadioShack or Wirefly for $49.99.
Asus 1015E Notebook
Asus 1015E Ubuntu Notebook To Launch Soon With $215 Price Tag
Asus is offering an alternative to the Windows 8 1015E notebook model: an 1015E-DS03 notebook
YouTube App
YouTube Shoppable Videos - Will Google Hit A New Jackpot?
YouTube is no longer a simple video-sharing site, it now offers consumers the chance to shop
Galaxy S3 Mini Jelly Bean Update
Android 4.2.2 Jelly Bean Update For Samsung Galaxy S3 Leaked
The new firmware comes with some Galaxy S4 features but it is not known whether the camera features
Samsung Galaxy Tab 3 8.0 Leaked Image
Samsung Galaxy Tab 3 8-Inch Specs, Photo Leak Online
Samsung recently announced the Galaxy Tab 3 7.0, but a new report with leaked specs and photo now

Ouya Android-Powered $99 Game Console
Ouya Will Be At E3 2013, But Not Where You Think
The Ouya team might not be on the E3 2013 show floors, but you can still give the console a test
Galaxy S3 Sapphire Black
Android 4.1.2 Jelly Bean Official Firmware Update For Samsung Galaxy S3 I9300 Via XXEMD2 [How To Install]
The update comes with some features like Group CastApp and Page Buddy.
MacBook Air
New MacBook Air To Debut In June With Intel's New Haswell Processor?
Apple is expected to update its hardware lineup as soon as June with a new MacBook Air likely
Google Nexus 4 White Version
White Nexus 4 To Launch On June 10 Rocking Latest Android 4.3
The white Nexus 4 that created a lot of buzz among rumor mills recently, finally has a launch date:
Copyright © 2013 Mobile & Apps All rights reserved. mobilenapps
Real Time Analytics